Sign in

Joe Birr-Pixton

@jbp.io
184 followers 162 following 104 posts

computers, computer security, cryptography. rather dull really. locale: cambridge, uk github: github.com/ctz & github.com/rustls

PostsRepliesMedia
Joe Birr-Pixton @jbp.io · 17/09/2026
"you know who else enjoyed the safety of memory?"
110
Joe Birr-Pixton @jbp.io · 15/09/2026
it's giving "rewrite docker in rust" energy
120
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 09/09/2026
rustls, our modern memory-safe TLS implementation is 10 years old! @jbp.io wrote a blog post reflecting on how we got here: rustls.dev/blog/2026-09...
rustls.dev
rustls: A Decade of Rustls
2548
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 13/08/2026
Happy to announce a new project: OxiSH, a modern, memory-safe SSH server. dirkjan.ochtman.nl/writing/2026... Prossimo has three criteria for suggesting memory-safe rewrites: (1) widely used, (2) on a security boundary and (3) performing a critical function. This is clearly true for SSH servers.
dirkjan.ochtman.nl
OxiSH: a modern, memory-safe SSH server – Dirkjan Ochtman
26714
Reposted by Joe Birr-Pixton
eliza🌻 @elizas.website · 07/08/2026
with times being what they are, it seems like you basically can't have a public open source repo without receiving LLM-written PRs. thus, after a great deal of thought, i have adopted the somewhat idiosyncratic Mycelium AI Policy in my personal projects: github.com/hawkw/myceli...
github.com
chore: introducing the Mycelium AI Policy (#566) · hawkw/mycelium@b77e854
2635546
Joe Birr-Pixton @jbp.io · 05/08/2026
Happy to hear your feedback on this Ellie, if you have the time
110
Reposted by Joe Birr-Pixton
RustConf @rustconf.com · 26/07/2026
🎂 Ten years of Rustls. At #rustconf2026, Rustls project founder Joe Birr-Pixton and open source maintainer Daniel McCarney look back on a decade building a memory-safe TLS library trusted across the industry. View on schedule: sched.co/2KHyL Register: bit.ly/45kJb9Y
0112
Reposted by Joe Birr-Pixton
RustConf @rustconf.com · 22/07/2026
📢 Session: "A Decade of Rustls": update from maintainers @jbp.io & Daniel McCarney at #rustconf! 10 years in, what's next for one of Rust's most widely used TLS libs? 🎟️: rustconf.com/register?utm_source=rustconf_x&utm_medium=social&utm_campaign=week_july20 rustconf2026.sched.com/event/2KHyL/...
093
Joe Birr-Pixton @jbp.io · 02/07/2026
Pleased to announce a new network transport security protocol: "TSL" (Transport Security Layer). Suspiciously wire compatible with TLS, but obviously unrelated. Future standardisation efforts will happen outside the IETF, and contributions made with the aesthetic of american politics are banned
2120
Reposted by Joe Birr-Pixton
da share z0ne @dasharez0ne.bsky.social · 27/02/2026
TRANS RIGHT'S ARE HUMAN RIGHT'S - dashare.zone ADMIN
A SKLETON HOLDIN UP A FINGER TO POLITICANS AND THE PEACES OF SHIT WHO WANT TO WRECK EVERYONES LIFES, IF SOME OF US ARE NOT FREE THEN NONE OF US ARE FREE, THE POLITICANS AND BILLIONAIRES WHO RUN THE COUNTRY MEET ON A SECRET ISLAND TO BREED SEX SLAVES BUT THEY WANNA TELL US THAT WE SHOULD BE SCARED OF SOMEONE TAKEN A SHIT IN A PUBLIC BATHROOM, OR MAD AT SOMEONE FOR HAVIN A DRIVERS LICENSE, FASHISM AINT CREEPIN ANY MORE ITS JOGGING, THEY BETTER GET THERE BIG ASS BUNKERS BUILT QUICK CAUSE THERE FULL OF MEAT AND WE GROW HUNGRIER BY THE DAY - DASHARE.ZONE ADMIN
02542936
Joe Birr-Pixton @jbp.io · 25/06/2026
Updated benchmark results from my computers on jbp.io/graviola/ Note that direct comparison between ML-KEM and other "key exchange" rows is not super helpful -- the ML-KEM rows sum all operations over two peers, whereas ECDH rows are the operations for one peer.
jbp.io
Graviola Benchmarking Results
010
Joe Birr-Pixton @jbp.io · 25/06/2026
I released Graviola 0.4.1 yesterday, which improves ML-KEM-768 performance via the parallel SHAKE strategy -- compared to mlkem-native as included in aws-lc it is now 30% quicker on aarch64 and 8% quicker on x86-64 for combined keygen+encaps+decaps.
1120
Joe Birr-Pixton @jbp.io · 22/06/2026
i think i saw this guy was in home alone 2 why's he doing your cryptography policies?
121
Joe Birr-Pixton @jbp.io · 18/06/2026
Pleased to announce my new development tool `cargo-cocaine-al-qaeda-disney-frozen.torrent`
080
Joe Birr-Pixton @jbp.io · 18/06/2026
See crates.io/crates/gravi... or updated benchmark results jbp.io/graviola/
crates.io
crates.io: Rust Package Registry
crates.io serves as a central registry for sharing crates, which are packages or libraries written in Rust that you can use to enhance your projects
030
Joe Birr-Pixton @jbp.io · 18/06/2026
I released Graviola 0.4.0 yesterday, with a new and quite quick ML-KEM-768 implementation. More perf work to do on this, but it is already quicker than libcrux-ml-kem, and competitive with mlkem-native on ARM64. And still builds mega fast! Consider supporting this work on github.com/sponsors/ctz
1235
Joe Birr-Pixton @jbp.io · 15/06/2026
A well-known constraint on architecture is that all new buildings must look like existing buildings. So clearly the answer is a "northstowe funnel"
000
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 10/06/2026
The recording of our talk at @canonicalltd.bsky.social's #UbuntuSummit is available now: www.youtube.com/watch?v=qKmR... Happy to answer questions here!
youtube.com
uPKI: improving certificate revocation on Linux | Ubuntu Summit 26.04
YouTube video by Canonical Ubuntu
062
Joe Birr-Pixton @jbp.io · 27/05/2026
boggle?
010
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 27/05/2026
@jbp.io and I will be presenting on our upki project to make TLS certificate verification more secure for non-browser Linux apps.
0193
Joe Birr-Pixton @jbp.io · 22/05/2026
here we see graphviz in its natural habitat
030
Joe Birr-Pixton @jbp.io · 18/05/2026
"No way to prevent this" says only cryptographic API where this regularly happens - barghest.asia/blog/cve-202... (previously jbp.io/2014/01/16/o... )
barghest.asia
CVE-2026-0073 Android adbd TLS client-authentication bypass
BARGHEST analysis of CVE-2026-0073, an Android adbd ADB-over-TCP authentication bypass enabling no-interaction RCE through cross-algorithm TLS certificate comparison.
030
Joe Birr-Pixton @jbp.io · 01/05/2026
At #rustweek I'll have new stickers celebrating a decade of rustls. First commit was ten years ago tomorrow
A stack of holographic stickers for the rustls TLS library
2322
Joe Birr-Pixton @jbp.io · 22/04/2026
Macbook Hair is particularly bad for this
110
Joe Birr-Pixton @jbp.io · 22/04/2026
i would think you of all people would understand the benefits of a laptop with fewer hair removal capabilities
100
Joe Birr-Pixton @jbp.io · 22/04/2026
youtu.be/rgZlzCd0DUU?... I guess this means I'm a tech influencer now? Thanks @frame.work
youtu.be
Framework [Next Gen] Event | 2026 Launch Event
YouTube video by Framework
131
Joe Birr-Pixton @jbp.io · 14/04/2026
is this a star wars thing?
100
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 10/04/2026
An update on rustls performance: it’s still pretty fast. www.memorysafety.org/blog/26q1-ru...
memorysafety.org
Q1 2026 Rustls Performance Update
Overview Offering top tier performance is a primary goal for the Rustls project. As such, the project has developed benchmarks representing some of the most performance critical functions and monitors them closely. The Rustls project periodically publishes test results that compare Rustls performance to other popular TLS libraries, OpenSSL and BoringSSL. The previously published test results are from July of 2025. The Rustls project is planning to start publishing performance reports more frequently going forward.
0236
Joe Birr-Pixton @jbp.io · 10/04/2026
Taxi Driver OST vibes
000
Reposted by Joe Birr-Pixton
tef @tef.bsky.social · 30/03/2026
keep hearing "PULL UP" "PULL UP" and "TERRAIN, TERRAIN" but i'm pretty sure there's nothing to worry about
34910
Joe Birr-Pixton @jbp.io · 15/03/2026
I am running an event at the same time - "An Evening Without Michael Gove." Tickets from £127.50
060
Reposted by Joe Birr-Pixton
Dirkjan Ochtman @djc.ochtman.nl · 13/03/2026
I wrote a blog post for the Alpha Omega Foundation on the work I did to surface RustSec advisories on crates.io: alpha-omega.dev/blog/surfaci...
crates.io
crates.io: Rust Package Registry
0122
Joe Birr-Pixton @jbp.io · 11/03/2026
github (2026, oil on canvas)
0170
Reposted by Joe Birr-Pixton
Deirdre Connolly¹ ² @durumcrustulum.com · 11/03/2026
Merkle Tree Certs! #realworldcrypto
141
Reposted by Joe Birr-Pixton
Thomas Ptacek @sockpuppet.org · 28/02/2026
None of you are giving me enough credit for not participating on the TLS working group mailing list. You're welcome. Everything I don't do, I don't do it for you.
2262
Joe Birr-Pixton @jbp.io · 24/02/2026
"If we publish this, suddenly people will start taking the cryptography opinions of the TLSWG very seriously. This would definitely happen thanks of the decades of demonstrated good decision making."
000
Reposted by Joe Birr-Pixton
tef @tef.bsky.social · 18/01/2026
if anything, i've found that the quality of his posts have gone down over time, i call this "doctorowification"
17410
Joe Birr-Pixton @jbp.io · 16/02/2026
One of the things I've been working on recently.
070
Joe Birr-Pixton @jbp.io · 08/02/2026
rust `use` statements are a conspiracy by big merge conflict to sell more conflicts
190
Joe Birr-Pixton @jbp.io · 06/02/2026
Life of a town councillor
Reporting a dead badger as a fly tipping incident
110
Reposted by Joe Birr-Pixton
Winnie the Pooh (Official) @indianawalsh.bsky.social · 19/01/2026
Gary Larson: In my cartoon I invented Cow Tools as a cautionary tale Cows: At long last, we have created the Cow Tools from classic newspaper comic Cow Tools
77140064011
Reposted by Joe Birr-Pixton
Filippo Valsorda @filippo.abyssdomain.expert · 09/01/2026
Here are some statistics (estimated via Poisson inference on the observed hit counts): Keys generated: 2^34.5 (95% CI: 2^33.6–2^35.0) Core-years: 56.7 (95% CI: 30.7–82.6) Average cores: ~5,200 (95% CI: 2,800–7,500) This is a lot, folks! Really grateful for this level of community support.
0202
Joe Birr-Pixton @jbp.io · 05/01/2026
I think you might have to grapple with schannel being quite bad? Like TLS1.3 is not available on Windows 10 (still ~50% of Windows installs)
110
Joe Birr-Pixton @jbp.io · 03/01/2026
dependabot/renovate have a natural preference for ICU4X
000
Joe Birr-Pixton @jbp.io · 01/01/2026
Delighted to be recognised by @openuk.bsky.social for my recent open source work!
040
Reposted by Joe Birr-Pixton
Sean McArthur @seanmonstar.com · 30/12/2025
To end the year, a new major version of #rustlang reqwest, v0.13.0 is out! 🚀 - This brings rustls by default, replacing native-tls. 🦀 - Some feature and method cleanup. - But easy to upgrade for most everyone. seanmonstar.com/blog/reqwest...
seanmonstar.com
reqwest v0.13 - rustls by default
reqwest v0.13 brings rustls by default, feature cleanup, but otherwise easy to upgrade.
1395
Reposted by Joe Birr-Pixton
Josh Bressers @josh.bressers.name · 29/12/2025
This week on #OpenSourceSecurity I chat with Dirkjan Ochtman and Joe Birr-Pixton about #Rustls. A lot has happened with Rustls in the last few years (and there's a lot more to come). Writing a TLS implementation is incredibly complicated, even when you don't have to worry about memory safety
opensourcesecurity.io
Rustls with Dirkjan and Joe
Josh talk to Dirkjan and Joe about Rustls (pronounced rustles), a Rust-based TLS library. Dirkjan and Joe are developers on Rustls. We talk about the history that got us to this point. The many many c...
053
Reposted by Joe Birr-Pixton
Sean McArthur @seanmonstar.com · 23/12/2025
Just published a new #rustlang reqwest release candidate: v0.13.0-rc.1. This has some breaking changes, the biggest was switching to rustls by default. I'd appreciate if you gave it a spin 🙏 github.com/seanmonstar/...
github.com
Release v0.13.0-rc.1 · seanmonstar/reqwest
👀 Discussion here if you give it try, thanks! Main breaking changes rustls is now default instead of native-tls rustls provider defaults to aws-lc instead of ring (rustls-no-provider exists if you...
13310